CVE-2026-87230
10.0Oracle · Oracle Hyperion Financial Management
A critical security vulnerability in Oracle Hyperion Financial Management allows unauthenticated remote attackers to modify or access sensitive financial data.
Executive summary
Oracle Hyperion Financial Management is susceptible to an unauthenticated remote exploit that grants attackers the ability to manipulate or exfiltrate sensitive financial records.
Vulnerability
This vulnerability exists in the Security component of the application. It allows an unauthenticated attacker with network access to perform unauthorized creation, deletion, or modification of critical data within the system.
Business impact
With a CVSS score of 10.0, this vulnerability presents a catastrophic risk to financial data integrity and confidentiality. Successful exploitation could allow attackers to alter financial reporting, misappropriate sensitive information, or bypass security controls, leading to severe regulatory and reputational damage.
Remediation
Immediate Action: Access the vendor security advisory at https://www.oracle.com/security-alerts/cspusep2026.html and apply the corresponding security patches.
Proactive Monitoring: Audit database and application logs for unauthorized write or delete operations that do not correlate with known administrative activity.
Compensating Controls: Restrict network access to the Hyperion Financial Management interface to known, trusted IP addresses using a firewall or VPN.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The potential for unauthorized modification of sensitive financial data makes this a high-priority incident. Security teams must ensure that the recommended vendor patches are tested and deployed immediately to protect the integrity of financial systems.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief critical section
Sources
- Oracle Advisory Vendor advisory